First published: Thu Apr 11 2013(Updated: )
Cisco IOS XE 3.4 before 3.4.4S, 3.5, and 3.6 on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 multicast packets, aka Bug ID CSCtz97563.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Software | =3.4.0as | |
Cisco IOS XE Software | =3.4.0s | |
Cisco IOS XE Software | =3.4.1s | |
Cisco IOS XE Software | =3.4.2s | |
Cisco IOS XE Software | =3.4.3s | |
Cisco IOS XE Software | =3.5.0s | |
Cisco IOS XE Software | =3.6.0s | |
Cisco ASR 1001 | ||
Cisco ASR 1002 Fixed Router | ||
Cisco ASR 1002-X | ||
Cisco ASR 1004 | ||
Cisco ASR 1006 | ||
Cisco ASR 1013 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1164 has a severity rating of medium, primarily due to its potential to cause a denial of service.
To mitigate CVE-2013-1164, it is recommended to upgrade to Cisco IOS XE versions 3.4.4S, 3.5, or 3.6 or later.
CVE-2013-1164 affects Cisco ASR 1000 series routers running affected versions of Cisco IOS XE.
CVE-2013-1164 is a denial of service vulnerability related to the improper handling of fragmented IPv6 multicast packets.
Yes, CVE-2013-1164 can be exploited remotely by attackers to trigger a card reload on affected devices.